First published: Fri Apr 08 2022(Updated: )
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | >=5.17<5.17.1 | |
Red Hat Enterprise Linux | =6.0 | |
Red Hat Enterprise Linux | =7.0 | |
Red Hat Fedora | =35 | |
NetApp Active IQ Unified Manager | ||
NetApp SolidFire Enterprise SDS | ||
NetApp SolidFire & HCI Management Node | ||
NetApp HCI Compute Node Firmware | ||
NetApp HCI Compute Node | ||
NetApp H300S Firmware | ||
NetApp H300S Firmware | ||
NetApp H500e Firmware | ||
NetApp H500e Firmware | ||
NetApp H700S | ||
NetApp H700S | ||
NetApp H300E | ||
NetApp H300E Firmware | ||
NetApp H500S Firmware | ||
NetApp H500e Firmware | ||
NetApp H700E | ||
NetApp H700E | ||
NetApp H410S | ||
NetApp H410S Firmware | ||
NetApp H410C | ||
NetApp H410C Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28796 is a vulnerability in the Linux kernel before version 5.17.1 that allows a use-after-free caused by a transaction_t race condition in the jbd2_journal_wait_updates function in fs/jbd2/transaction.c.
CVE-2022-28796 is considered high severity with a CVSS score of 7.
The Linux kernel versions before 5.17.1, Redhat Enterprise Linux versions 6.0 and 7.0, and Fedoraproject Fedora version 35 are affected by CVE-2022-28796.
To fix CVE-2022-28796, it is recommended to update to the Linux kernel version 5.17.1 or later.
You can find more information about CVE-2022-28796 in the following references: [Link 1](https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1), [Link 2](https://github.com/torvalds/linux/commit/cc16eecae687912238ee6efbff71ad31e2bc414e), [Link 3](https://security.netapp.com/advisory/ntap-20220506-0006/).